question

SSG-2301 avatar image
0 Votes"
SSG-2301 asked SeeyaXi-msft commented

SPN registration for sql service accaount

Hi,

Users are unable to connect to sql server remotely. Receiving error: Target principal name is incorrect.

The server has been recently changed from one domain to another & the SQL service account has been updated.

I am trying to list the SPNs registered for sql service account & want to register the SPNs so that user can connect using Kerberos authentication in order to fix the above issue.

When trying to list the SPN registered I am getting the below error:
cmd: setspn –L <service account name>
Error: Ldap Error(0x80090302 -- ): ldap_bind

Can someone let me know what's the issue here & how to fix this.

Thank You.

sql-server-general
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @SSG-2301 ,

We have not received a response from you. Did the reply could help you? If the response helped, do "Accept Answer". If it doesn't work, please let us know the progress. By doing so, it will benefit all community members who are having this similar issue. Your contribution is highly appreciated.

Best regards,
Seeya

0 Votes 0 ·
OlafHelper-2800 avatar image
0 Votes"
OlafHelper-2800 answered
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

SeeyaXi-msft avatar image
0 Votes"
SeeyaXi-msft answered

Hi @SSG-2301,

Welcome to Microsoft Q&A!
If the SQL Server service account is Local System or Network Service, then the SPN needs to be registered under the machine account. If SQL Server is running under a domain account, then the SPN needs to be registered under that domain account. You need to make sure that <service account name> is filled in correctly.

Best regards,
Seeya


If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

TomPhillips-1744 avatar image
0 Votes"
TomPhillips-1744 answered

The simplest way to fix SPN issues, is to temporarily grant the SQL Server service account domain admin rights, restart the SQL Server service (it will create the SPNs), and then remove the domain admin rights, and restart the SQL Server service again.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.